Simpl-Resultat/.forgejo/workflows/audit.yml
le king fu 263ebe1495
All checks were successful
PR Check — Frontend / frontend (pull_request) Successful in 1m43s
PR Check — Rust / rust (pull_request) Successful in 8m55s
ci: split check.yml, drop dead caches, prebuild cargo-audit (#232)
The rust job cost 21m44s on every PR while only ~1 PR in 40 touches
src-tauri/, and the runner has capacity 1 — the frontend job queues behind
it, so every PR paid ~24.5 min of feedback.

Measured on run 326 (2026-07-21), 12m15s of that was pure waste:
- 6m54s tarring target/ and the cargo registry for saves that time out
  against the runner's unreachable cache server (#234). The restore times
  out into a miss too, so nothing was ever cached at either end.
- 4m41s recompiling cargo-audit from source on every run.
- ~40s on the two doomed restores.

Split check.yml into check-rust.yml (paths: src-tauri/**) and
check-frontend.yml (paths-ignore denylist), drop every actions/cache step
until #234 is fixed, and install cargo-audit as a prebuilt binary via
taiki-e/install-action. The audit step keeps continue-on-error — advisories
are informational and can land on unrelated crates — but loses the `|| true`
that also hid tooling failures; the install step is blocking.

The frontend filter is a denylist on purpose: that job costs ~2.5 min, so
running it needlessly is cheap while silently not running it is not. The
expensive job keeps a strict allowlist.

Neither workflow filters on `branches:` anymore. `branches: [main]` never
matched a PR stacked on another feature branch, which is what /autopilot
produces: PRs #305-#308 of the feature-gating milestone ran no CI at all.

Adds audit.yml for daily RustSec coverage, since check-rust.yml now only
runs on Rust PRs. It skips the Rust toolchain entirely — cargo-audit only
reads Cargo.lock — so it costs ~1-2 min rather than the ~22 a scheduled
check-rust would burn daily on a capacity-1 runner.

The GitHub mirror is left untouched (#233: it receives no PRs).

Expected: Rust PR ~9-10 min, frontend-only PR ~2.5 min instead of ~24.5.

Resolves #232
2026-07-24 20:26:35 -04:00

58 lines
1.9 KiB
YAML

name: Security audit
# Daily RustSec coverage (#232).
#
# check-rust.yml only runs when src-tauri/ changes, which is roughly 1 PR in
# 40 — without this workflow a new advisory published against an unchanged
# dependency would go unnoticed for weeks.
#
# Runs without a Rust toolchain: cargo-audit only reads Cargo.lock, so the
# binary is invoked directly instead of as a `cargo` subcommand. That keeps
# this to ~1-2 min rather than the ~22 min a scheduled check-rust would cost
# every day on a capacity-1 runner.
#
# Note: PATH is deliberately NOT overridden at job level (unlike check-rust,
# which needs /root/.cargo/bin for the toolchain) so that the install dir
# taiki-e/install-action appends to $GITHUB_PATH stays effective.
on:
schedule:
# 06:00 UTC daily
- cron: '0 6 * * *'
workflow_dispatch:
concurrency:
group: ci-audit-${{ github.ref }}
cancel-in-progress: true
permissions:
contents: read
jobs:
audit:
runs-on: ubuntu
container: ubuntu:22.04
steps:
- name: Install Node.js 20
run: |
apt-get update
apt-get install -y --no-install-recommends \
curl ca-certificates git tar gzip
# Node.js is required by actions/checkout and taiki-e/install-action
# (JavaScript actions need `node` in the container PATH).
curl -fsSL https://deb.nodesource.com/setup_20.x | bash -
apt-get install -y nodejs
node --version
- name: Checkout
uses: https://github.com/actions/checkout@v4
- name: Install cargo-audit
uses: https://github.com/taiki-e/install-action@v2
with:
tool: cargo-audit
# Unlike the PR run in check-rust.yml, this one is meant to fail loudly:
# it IS the notification channel for a newly published advisory.
- name: cargo audit
run: cargo-audit audit --file src-tauri/Cargo.lock